Phishing Hack
What happened
On August 21, 2024, a victim lost $55.43 million in DAI after signing a phishing transaction that compromised their DeFi Saver Proxy, allowing the attacker to drain all the funds.
The exploit began when the victim, using the address 0xf2B88943…e13048, executed a setOwner transaction that inadvertently transferred ownership of their DeFi Saver Proxy contract to a phishing address 0x0000db5c…e70000. This phishing transaction resulted in the victim losing control of their proxy contract. Six hours later, when the victim attempted to execute a transaction, it failed because they were no longer the owner of the proxy.
Subsequently, the attacker changed the ownership of the proxy to 0x5D4b2A02…0459d4, allowing them to drain all the DAI from the compromised contract.
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.